WARNING - OLD ARCHIVES

This is an archived copy of the Xen.org mailing list, which we have preserved to ensure that existing links to archives are not broken. The live archive, which contains the latest emails, can be found at http://lists.xen.org/
   
 
 
Xen 
 
Home Products Support Community News
 
   
 

xen-users

[Xen-users] iptables and ipvsadm in domU

To: xen-users@xxxxxxxxxxxxxxxxxxx
Subject: [Xen-users] iptables and ipvsadm in domU
From: "Fong Vang" <sudoyang@xxxxxxxxx>
Date: Tue, 1 May 2007 16:33:02 -0700
Delivery-date: Tue, 01 May 2007 16:31:39 -0700
Dkim-signature: a=rsa-sha1; c=relaxed/relaxed; d=gmail.com; s=beta; h=domainkey-signature:received:received:message-id:date:from:to:subject:mime-version:content-type; b=ASw52B9zN3g6FZNjQI61/gwfKdEmVA/a3Lvb5TA6JYcmXjDLrsAHg0zdMFzJYHqa3GjYazZRJNBI+YYy6GseWieplpNHZodW6SX7cFioECLOYuXqhV0CreWJqR2U2RjEHV7XeeGfS9a33LJHq1nBs1eEZpqC8z7RAOTkBIU7Uew=
Domainkey-signature: a=rsa-sha1; c=nofws; d=gmail.com; s=beta; h=received:message-id:date:from:to:subject:mime-version:content-type; b=Yx1gWDhBH8Aq1MEJHWDGbLrP9Lp6lzoVxyX5d7pOhmANE9IAmDMcIdotfxRrfBnq8fGvGi5X4vz/bjUMytjIBWEjCzXZnJZUQga+iXC9Ldcnle/zZzwV6XLH+UcLYate2Yo4g/U6y6TVsJgzq2TAgroqCwzZ/v4aN2KG14Ii0wQ=
Envelope-to: www-data@xxxxxxxxxxxxxxxxxx
List-help: <mailto:xen-users-request@lists.xensource.com?subject=help>
List-id: Xen user discussion <xen-users.lists.xensource.com>
List-post: <mailto:xen-users@lists.xensource.com>
List-subscribe: <http://lists.xensource.com/cgi-bin/mailman/listinfo/xen-users>, <mailto:xen-users-request@lists.xensource.com?subject=subscribe>
List-unsubscribe: <http://lists.xensource.com/cgi-bin/mailman/listinfo/xen-users>, <mailto:xen-users-request@lists.xensource.com?subject=unsubscribe>
Sender: xen-users-bounces@xxxxxxxxxxxxxxxxxxx
The documentation for Xen mentions that iptables in dom0 may affect domUs.  If iptables and ipvsadm is heavily used in a domU, how does this impact dom0?

In my particular case, I want both dom0 and ONE domU (FW_domu) to be visible to the external network (eth1).  There will be several other domU's that will be behind FW_domU).  

as far as the domUs are concerned, this is the layout.

       FW_domU
          |
       LB_domU
          |
    +-----+--+--------+
    |        |        |
    domU1    domU2   domU3

what's the best way to set this up.  LB_domU runs LVS (ipvsadm).  Is this configuration even supported in Xen.

Thanks for any help.

_______________________________________________
Xen-users mailing list
Xen-users@xxxxxxxxxxxxxxxxxxx
http://lists.xensource.com/xen-users
<Prev in Thread] Current Thread [Next in Thread>